Most chains that brag about "fast finality" are really bragging about probabilistic finality — you just wait long enough that reversal becomes statistically absurd. Dusk doesn't do that. It commits to actual settlement finality, and the mechanism behind it is worth sitting with longer than the marketing page allows.
Segregated Byzantine Agreement splits block production into two jobs that never touch each other. Generation is handled by a Block Generator selected through Proof-of-Blind-Bid — a sortition process where the stake amount that determines your odds of winning stays hidden, not just your identity. Validation is a separate job, run by a rotating committee of Provisioners who vote the block through Reduction and then Agreement. Two phases, two different sets of actors, no single role that both proposes and finalizes.
Why does that separation matter more than it sounds? Because most consensus attacks target the overlap — a leader who can propose AND has outsized influence over confirmation. Segregating those roles, and hiding the bid weights that decide who gets picked to generate, removes a target that would otherwise be easy to grief or bribe. Once a certificate forms in the Agreement phase, it isn't soft-final waiting for six more confirmations — it's final. That's the part institutions actually care about, not the privacy branding.
The trade-off nobody advertises: this only works because voting power reshuffles every round. Static validator sets are easier to reason about and easier to audit from the outside, but they're also easier to map and target. Dusk bet on unpredictability over legibility.
Curious where people land on this — for a chain courting regulated securities settlement, is round-by-round validator reshuffling a security feature, or does it just move the attack surface from "who's the leader" to "can you predict the sortition output"?
#dusk $DUSK @Dusk
Segregated Byzantine Agreement splits block production into two jobs that never touch each other. Generation is handled by a Block Generator selected through Proof-of-Blind-Bid — a sortition process where the stake amount that determines your odds of winning stays hidden, not just your identity. Validation is a separate job, run by a rotating committee of Provisioners who vote the block through Reduction and then Agreement. Two phases, two different sets of actors, no single role that both proposes and finalizes.
Why does that separation matter more than it sounds? Because most consensus attacks target the overlap — a leader who can propose AND has outsized influence over confirmation. Segregating those roles, and hiding the bid weights that decide who gets picked to generate, removes a target that would otherwise be easy to grief or bribe. Once a certificate forms in the Agreement phase, it isn't soft-final waiting for six more confirmations — it's final. That's the part institutions actually care about, not the privacy branding.
The trade-off nobody advertises: this only works because voting power reshuffles every round. Static validator sets are easier to reason about and easier to audit from the outside, but they're also easier to map and target. Dusk bet on unpredictability over legibility.
Curious where people land on this — for a chain courting regulated securities settlement, is round-by-round validator reshuffling a security feature, or does it just move the attack surface from "who's the leader" to "can you predict the sortition output"?
#dusk $DUSK @Dusk